Privacy Policy
Last updated: September 10, 2026.
Rentshelf processes the data needed to provide product rental workflows for Shopify merchants.
Company
Rentshelf is operated by SKYTECH SERVICES LTD, 124 City Road, London, England, EC1V 2NX.
Data we process
- Merchant store details, billing status, and app configuration.
- Shopify product identifiers, rental pricing, availability, locations, add-ons, and booking settings.
- Order and booking details needed to manage rentals, returns, reminders, and customer self-service links.
- Customer contact details such as name, email, phone, and order identifiers when needed for rental booking communication.
How we use data
We use this data to operate the app, sync rental bookings with Shopify orders, provide merchant support, secure the service, and comply with Shopify data protection requirements.
Optional Google Calendar connection
When a merchant connects Google Calendar, Rentshelf stores the Google account email, encrypted authorization credentials, selected calendar identifiers and synchronization status. We read the calendar list so the merchant can choose a destination. We create, update and remove rental events only in the destination calendars selected by the merchant. Rental events contain booking references, product and rental details. Customer name and email are included only when the merchant enables that option. Rentshelf does not send Google Calendar customer invitations.
If a merchant enables busy-calendar rules, we read event dates, times, availability status and Rentshelf event identifiers from the selected calendars, and cache blocked dates to calculate product availability. This integration does not import personal event titles or descriptions into Rentshelf. Google Calendar data is used to provide this integration, not for advertising, sale, or training general-purpose AI models.
Disconnecting in Rentshelf removes stored authorization credentials and busy-date rules and requests Google access revocation. Merchants can also revoke access through their Google Account. Existing Google events are kept on disconnect; account and event identifiers may remain to prevent duplicates when reconnecting. Uninstalling removes credentials, and Shopify shop-redaction requests delete connection data and event mappings. Contact us below to request deletion. Data is processed using our hosting providers to operate the integration and shared with Google as instructed by the merchant.
Rentshelf's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Google user data sharing and disclosure
Rentshelf does not sell Google user data or share it with advertisers, data brokers, information resellers, or other third parties for their own purposes. We disclose Google user data only in the following limited circumstances:
- To Google, through the Google Calendar API, when the merchant asks Rentshelf to read selected calendar availability or create, update, or remove rental events.
- To Cloudflare, our infrastructure and database service provider, only as needed to host, secure, and operate the Rentshelf service. Service providers process this data on our behalf and may not use it for their own advertising or unrelated purposes.
- When required by applicable law, regulation, legal process, or a valid governmental request, or when necessary to protect the rights, safety, and security of users, Rentshelf, or the public.
- As part of a merger, acquisition, financing, reorganization, or sale of assets, subject to this Privacy Policy and appropriate confidentiality protections. We will notify affected users when required by law.
We do not otherwise transfer or disclose Google user data unless the merchant gives us explicit consent. Human access is limited to cases where it is necessary for security, support requested by the merchant, legal compliance, or service operations permitted by Google policy.
Protection of Google user data
Rentshelf uses administrative, technical, and organizational safeguards designed to protect Google user data. Data is encrypted in transit using HTTPS/TLS. Google OAuth authorization credentials are encrypted at rest using authenticated AES-256-GCM encryption, with encryption keys stored separately as protected environment secrets. Access to production data and secrets is restricted to authorized personnel and service processes that need it to operate or support the integration.
We request only the Google permissions needed for the calendar features, use private calendar events, avoid customer invitations, and exclude personal event titles, descriptions, and attendees from the busy-date cache. We do not intentionally log Google access or refresh tokens. We use access controls, tenant separation, short-lived OAuth state, and monitoring to reduce unauthorized access, disclosure, alteration, or loss. No method of storage or transmission is completely secure, but we review and update these safeguards as the service changes.
Website analytics and cookies
With your permission, our public website uses Google Analytics to measure visits, traffic sources and clicks to our Shopify App Store listing. Analytics cookies are only enabled after you choose Allow analytics. You can decline or withdraw permission using Cookie preferences. We do not send rental booking details, customer contact information or private app pages through this website analytics tag.
Shopify App Store analytics helps us understand listing views and app installations through Shopify's analytics integration. Google and Shopify process this information under their applicable policies. See Google's privacy policy. Contact us using the address below about your data or privacy choices.
Retention and deletion
Shopify compliance webhooks are implemented for customer data requests, customer redaction, and shop redaction. Privacy requests can be sent to info@rentshelf.app.